A SOC receives an alert that an internal host is communicating with a known malicious IP. The firewall is blocking the traffic. Which ADDITIONAL action should the SOC take?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because a host attempting to communicate with a malicious IP indicates a likely compromise regardless of whether the firewall blocked the connection. The source host must be investigated for malware, persistence mechanisms, and lateral movement.
Full explanation below image
Full Explanation
B is correct because a host attempting to communicate with a malicious IP indicates a likely compromise regardless of whether the firewall blocked the connection. The source host must be investigated for malware, persistence mechanisms, and lateral movement. A is wrong because the firewall block does not address the underlying compromise. C is wrong because DNS blocking alone is insufficient and does not address the compromised host. D is wrong because deferring investigation allows the attacker to maintain persistence and cause further damage.